システムユーザーと外部ユーザーの二要素認証
2 段階認証の仕組み
-
NetScaler、GUI、CLI、API、SSHにわたる二要素認証(2FA)。
-
システムユーザーの外部認証は有効で、ローカル認証は無効になっています。
-
システムユーザー向けのポリシーベースのローカル認証による外部認証が有効になっています。
-
ローカル認証が有効になっているシステムユーザーの外部認証は無効になっています。
-
システムユーザーの外部認証が有効で、ローカル認証が有効になっています。
-
特定の LDAP ユーザーに対して外部認証が有効になっています
ユースケース 1: Citrix のADC、GUI、CLI、API、SSHインターフェイスにわたる二要素認証 (2FA)
ユースケース 2: LDAP、RADIUS、Active Directory、TACACS などの外部認証サーバーで 2 要素認証がサポートされています
-
RADIUS
-
LDAP
-
Active Directory
-
TACACS
ユースケース 3: システムユーザーの外部認証を有効にし、ローカル認証を無効にする
-
LDAP ポリシーの認証アクションを追加
-
LDAP ポリシーの認証ポリシーを追加
-
RADIUS ポリシーの認証アクションを追加
-
RADIUS ポリシーの認証ポリシーを追加
-
認証ログインスキーマの追加
-
認証ポリシーラベルを RADIUS サーバに追加してバインドする
-
LDAP ポリシー用バインドシステムグローバル認証
-
システムパラメータのローカル認証を無効にする
LDAP サーバーの認証アクションを追加 (第 1 レベルの認証)
add authentication ldapaction <ldap action name> -serverip <IP> -ldapbase <> -ldapbinddn <binddn name> -ldapbinddnpassword <password>-ldaploginname <loginname> -groupattrname <grp attribute name> -subAttributename <string>-ssoNameAttribute <string>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name -ssoNameAttribute name
LDAP サーバーの認証ポリシーの追加 (第 1 レベルの認証)
add authentication policy <ldap policy name> -rule true -action <ldap action name>
add authentication policy pol1 -rule true -action ldapact1
RADIUS サーバの認証アクションの追加 (第 2 レベル認証)
add authentication radiusaction <rad action name> -serverip <rad server ip> -radkey <key> -radVendorID <ID >-radattributetype <rad attribute type>
add authentication radiusaction radact1 -serverip 1.1.1.1 -radkey 123 -radVendorID 1234 -radAttributeType 2
RADIUSサーバの認証ポリシーを追加 (第2レベル認証)
add authentication policy <radius policy name> -rule true -action <rad action name>
add authentication policy radpol11 -rule true -action radact1
認証ログインスキーマの追加
add authentication loginSchema <login schema name> -authenticationSchema LoginSchema/SingleAuth.xml
add authentication loginSchema radschema -authenticationSchema LoginSchema/SingleAuth.xml
認証ポリシーラベルを RADIUS サーバに追加してバインドする
add authentication policylabel <labelName> [-type ( AAATM_REQ | RBA_REQ )] [-comment <string>][-loginSchema <string>]
bind authentication policylabel <labelName> -policyName <string> -priority <positive_integer> [-gotoPriorityExpression <expression>][-nextFactor <string>]
add authentication policylabel label1 -type RBA_REQ -loginSchema radschema
bind authentication policylabel label1 -policyName radpol11 -priority 1
LDAP ポリシー用バインド認証システムグローバル
bind system global ldappolicy -priority <priority> -nextFactor <policy label name>
bind system global pol11 -priority 1 -nextFactor label1
システムパラメータのローカル認証を無効にする
set system parameter -localauth disabled
ユースケース 4: ローカル認証ポリシーがアタッチされたシステムユーザーの外部認証を有効にする
-
LDAP サーバーの認証アクションを追加
-
LDAP ポリシーの認証ポリシーを追加
-
ローカル認証ポリシーを追加
-
認証ポリシーラベルを追加
-
LDAP ポリシーをシステムグローバルとしてバインドする
-
システムパラメータのローカル認証を無効にする
LDAP サーバーの認証アクションを追加 (第 1 レベルの認証)
add authentication ldapaction <ldap action name> -serverip <IP> -ldapbase <> -ldapbinddn <binddn name> -ldapbinddnpassword <password>-ldaploginname <loginname> -groupattrname <grp attribute name> -subAttributename <string>-ssoNameAttribute <string>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name -ssoNameAttribute name –ssoNameAttribute name
LDAP サーバーの認証ポリシーの追加 (第 1 レベルの認証)
add authentication policy <ldap policy name> -rule true -action <ldap action name>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name -ssoNameAttribute name
システムユーザー用のローカル認証ポリシーの追加 (第 2 レベル認証)
add authentication policy <policy> -rule <rule> -action <action name>
add authentication policy local_policy -rule true -action LOCAL
認証ポリシーラベルを追加してバインドする
add authentication policylabel <labelName> [-type ( AAATM_REQ | RBA_REQ )] [-comment <string>][-loginSchema <string>] bind authentication policylabel <labelName> -policyName <string> -priority <positive_integer> [-gotoPriorityExpression <expression>][-nextFactor <string>]
add authentication policylabel label1 -type RBA_REQ -loginSchema radschema bind authentication policylabel label1 -policyName radpol11 -priority 1 -gotoPriorityExpression NEXT
システムパラメータのローカル認証を無効にする
set system parameter -localauth disabled
ユースケース 5: システムユーザーの外部認証を無効にし、ローカル認証を有効にする
システムユーザーパスワードを有効にし、外部認証を無効にするには
add system user <name> <password> -externalAuth DISABLED
add system user user1 password1 –externalAuth DISABLED
ユースケース 6: システムユーザーの外部認証が有効で、ローカル認証が有効になっている
-
LDAP サーバーの認証アクションを追加
-
LDAP ポリシーの認証ポリシーを追加
-
RADIUS ポリシーの認証アクションを追加
-
RADIUS ポリシーの認証ポリシーを追加
-
認証ログインスキーマの追加
-
認証ポリシーラベルを追加
-
ログインスキーマのバインド認証ポリシーラベル
-
RADIUS ポリシー用グローバル認証システムをバインドする
-
LDAP ポリシー用バインド認証システムグローバル
LDAP サーバーの認証アクションを追加
add authentication ldapaction <ldap action name> -serverip <IP> -ldapbase <> -ldapbinddn <binddn name> -ldapbinddnpassword <password>-ldaploginname <loginname> -groupattrname <grp attribute name> -subAttributename <>-ssoNameAttribute <>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name -ssoNameAttribute name
LDAP ポリシーの認証ポリシーを追加
add authentication policy <policy name> --rule true -action <ldap action name>
add authentication policy pol1 -rule true -action ldapact1
RADIUS サーバの認証アクションを追加
add authentication radiusaction <rad action name> -serverip <rad server ip> -radkey <key> -radVendorID <ID >-radattributetype <rad attribute type>
add authentication radiusaction radact1 -serverip 1.1.1.1 -radkey 123 -radVendorID 1234 -radAttributeType 2
RADIUS サーバ用の高度な認証ポリシーの追加
add authentication policy <policy name> -rule true -action <rad action name>
add authentication policy radpol11 -rule true -action radact1
認証ログインスキーマの追加
add authentication loginSchema <name> -authenticationSchema <string>
add authentication loginSchema radschema -authenticationSchema LoginSchema/SingleAuth.xml
認証ポリシーラベルをユーザーログイン用の RADIUS 認証ポリシーに追加してバインドする
add authentication policylabel <labelName> [-type ( AAATM_REQ | RBA_REQ )] [-comment <string>][-loginSchema <string>]
add authentication policylabel label1 -type RBA_REQ -loginSchema radschema bind authentication policylabel <labelName> -policyName <string> -priority <positive_integer> [-gotoPriorityExpression <expression>][-nextFactor <string>]
bind authentication policylabel label1 -policyName rad pol11 -priority 1
バインド認証ポリシーグローバル
bind system global [<policyName> [-priority <positive_integer>] [-nextFactor <string>] [-gotoPriorityExpression <expression>]]
bind system global radpol11 -priority 1 -nextFactor label11
ユースケース 7: 特定の外部ユーザーに対してのみ外部認証を有効にする
-
LDAP サーバーの認証アクションを追加
-
LDAP ポリシーの認証ポリシーを追加
-
RADIUS ポリシーの認証アクションを追加
-
RADIUS ポリシーの認証ポリシーを追加
-
認証ログインスキーマの追加
-
認証ポリシーラベルを追加
-
ログインスキーマのバインド認証ポリシーラベル
-
RADIUS ポリシー用グローバル認証システムをバインドする
LDAP サーバーの認証アクションを追加
add authentication ldapaction <ldap action name> -serverip <IP> -ldapbase <> -ldapbinddn <binddn name> -ldapbinddnpassword <password>-ldaploginname <loginname> -groupattrname <grp attribute name> -subAttributename <>-ssoNameAttribute <>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name -ssoNameAttribute name
LDAP ポリシーの認証ポリシーを追加
add authentication policy <policy name> --rule true -action <ldap action name>
add authentication policy pol1 -rule true -action ldapact1
RADIUS サーバの認証アクションを追加
add authentication radiusaction <rad action name> -serverip <rad server ip> -radkey <key> -radVendorID <ID >-radattributetype <rad attribute type>
add authentication radiusaction radact1 -serverip 1.1.1.1 -radkey 123 -radVendorID 1234 -radAttributeType 2
RADIUS サーバ用の高度な認証ポリシーの追加
add authentication policy <policy name> -rule true -action <rad action name>
add authentication policy radpol11 -rule true -action radact1
認証ログインスキーマの追加
add authentication loginSchema <name> -authenticationSchema <string>
add authentication loginSchema radschema -authenticationSchema LoginSchema/SingleAuth.xml
認証ポリシーラベルをユーザーログイン用の RADIUS 認証ポリシーに追加してバインドする
add authentication policylabel <labelName> [-type ( AAATM_REQ | RBA_REQ )] [-comment <string>][-loginSchema <string>]
add authentication policylabel label1 -type RBA_REQ -loginSchema radschema bind authentication policylabel <labelName> -policyName <string> -priority <positive_integer> [-gotoPriorityExpression <expression>][-nextFactor <string>]
bind authentication policylabel label1 -policyName radpol11 -priority
バインド認証ポリシーグローバル
bind system global [<policyName> [-priority <positive_integer>] [-nextFactor <string>] [-gotoPriorityExpression <expression>]]
bind system global radpol11 -priority 1 -nextFactor label11
-
LDAP サーバーの認証アクションを追加
-
LDAP サーバーの認証ポリシーを追加
-
LDAP サーバー用グローバル認証システム
LDAP サーバーの認証アクションを追加
add authentication ldapaction <ldap action name> -serverip <IP> -ldapbase <> -ldapbinddn <binddn name> -ldapbinddnpassword <password>-ldaploginname <loginname> -groupattrname <grp attribute name> -subAttributename <>-searchFilter<>
add authentication ldapaction ldapact1 -serverip 1.1.1.1 -ldapbase base -ldapbindDn name -ldapbindDNpassword password -ldapLoginName name -groupAttrName name -subAttributeName name - searchFilter "memberOf=CN=grp4,CN=Users,DC=aaatm-test,DC=com"
LDAP サーバーの認証ポリシーを追加
add authentication policy <policy name> --rule true -action <ldap action name>
add authentication policy pol1 -rule true -action ldapact1
LDAP ポリシー用バインド認証システムグローバル
bind system global ldappolicy -priority <priority> -nextFactor <policy label name>
bind system global pol11 -priority 1 -nextFactor label11
2 要素認証用にカスタマイズされたプロンプトメッセージを表示
/flash/nsconfig/loginschema/LoginSchemaのSingleAuth.xml ファイルで 2 要素パスワードフィールドを設定する場合
<?xml version="1.0" encoding="UTF-8"?>
<AuthenticateResponse xmlns="http://citrix.com/authentication/response/1">
<Status>success</Status>
<Result>more-info</Result>
<StateContext/>
<AuthenticationRequirements>
<PostBack>/nf/auth/doAuthentication.do</PostBack>
<CancelPostBack>/nf/auth/doLogoff.do</CancelPostBack>
<CancelButtonText>Cancel</CancelButtonText>
<Requirements>
<Requirement><Credential><ID>login</ID><SaveID>ExplicitForms-Username</SaveID><Type>username</Type></Credential><Label><Text>singleauth_user_name</Text><Type>nsg-login-label</Type></Label><Input><AssistiveText>singleauth_please_supply_either_domain\username_or_user@fully.qualified.domain</AssistiveText><Text><Secret>false</Secret><ReadOnly>false</ReadOnly><InitialValue/><Constraint>.+</Constraint></Text></Input></Requirement>
<Requirement><Credential><ID>passwd</ID><SaveID>ExplicitForms-Password</SaveID><Type>password</Type></Credential><Label><Text>SecondPassword:</Text><Type>nsg-login-label</Type></Label><Input><Text><Secret>true</Secret><ReadOnly>false</ReadOnly><InitialValue/><Constraint>.+</Constraint></Text></Input></Requirement>
<Requirement><Credential><Type>none</Type></Credential><Label><Text>singleauth_first_factor</Text><Type>nsg_confirmation</Type></Label><Input/></Requirement>
<Requirement><Credential><ID>saveCredentials</ID><Type>savecredentials</Type></Credential><Label><Text>singleauth_remember_my_password</Text><Type>nsg-login-label</Type></Label><Input><CheckBox><InitialValue>false</InitialValue></CheckBox></Input></Requirement>
<Requirement><Credential><ID>loginBtn</ID><Type>none</Type></Credential><Label><Type>none</Type></Label><Input><Button>singleauth_log_on</Button></Input></Requirement>
</Requirements>
</AuthenticationRequirements>
</AuthenticateResponse>
NetScaler GUI を使用した二要素認証の設定
-
NetScaler ADCアプライアンスにログオンします。
-
「 認証ポリシーの作成 」ページで、次のパラメータを設定します。
-
Name:ポリシーの名前
-
アクションタイプ。LDAP、Active Directory、RADIUS、TACACS などとしてアクションタイプを選択してください
-
操作。ポリシーに関連付ける認証アクション (プロファイル)。既存の認証アクションを選択するか、プラス記号をクリックして適切なタイプのアクションを作成できます。
-
式。詳細なポリシー表現を提供してください。
-
-
-
式。詳細なポリシー表現を提供してください。
-
-
[作成] をクリックします。
-
「 認証ポリシーの作成 」ページで、次のパラメータを設定します。
-
Name:ポリシーの名前
-
アクションタイプ。LDAP、Active Directory、RADIUS、TACACS などとしてアクションタイプを選択してください
-
操作。ポリシーに関連付ける認証アクション (プロファイル)。既存の認証アクションを選択するか、+ アイコンをクリックして適切なタイプのアクションを作成できます。
-
式。詳細なポリシー表現を提供
-
-
-
式。詳細なポリシー表現を提供してください。
-
-
[作成] をクリックします。
-
「 認証ポリシー 」ページで、「 グローバルバインディング」をクリックします。
-
「 グローバル認証ポリシーバインディングの作成 」ページで、第1レベルの認証ポリシーを選択し、「 バインドの追加」をクリックします。
-
ポリシーバインディングページで 、認証ポリシーを選択し、次のポリシーバインディングパラメータを設定します。
-
次の要因。第 2 レベルの認証ポリシーラベルを選択します。
-
-

-
[完了] をクリックします。
-
NetScaler ADCアプライアンスにログオンして、第2レベルの認証を行います。これで、ユーザーは 2 番目のパスワードを入力できます。両方のパスワードが正しい場合にのみ、ユーザーはNetScaler ADCアプライアンスにアクセスできます。